apiVersion: apps/v1 kind: Deployment metadata: name: {{ .Release.Name }}-ingest labels: {{- include "sentry.labels" . | nindent 4 }} {{- include "sentry.selectorLabels" (list $ "ingest") | nindent 4 }} spec: replicas: {{ .Values.ingest.replicas }} selector: matchLabels: {{- include "sentry.selectorLabels" (list $ "ingest") | nindent 6 }} template: metadata: labels: {{- include "sentry.selectorLabels" (list $ "ingest") | nindent 8 }} spec: initContainers: {{- include "sentry.waitForTCP" (list "redpanda" (printf "%s-redpanda" .Release.Name) "9092") | nindent 8 }} {{- include "sentry.waitForTCP" (list "clickhouse" (printf "%s-clickhouse" .Release.Name) "9000") | nindent 8 }} containers: - name: ingest image: "{{ .Values.ingest.image.repository }}:{{ .Values.ingest.image.tag }}" imagePullPolicy: {{ .Values.global.imagePullPolicy }} {{- if and .Values.enterprise.enabled .Values.ingest.requireTenantCredential }} # -mode=server only: this Deployment stops running the # ClickHouse-writing consumer half (the default -mode=all) # once per-tenant write-routing is on -- enterprise-ingest.yaml # (below) takes over consuming sentry.logs.raw instead, so it # can write each tenant's records to their own database rather # than the one shared table ingest's own consumer always # writes to. The agent-facing server half (PushBatch, tenant # tagging via TenantResolver) keeps running here unconditionally # either way -- only which process consumes the topic changes. args: ["-mode=server"] {{- end }} env: - name: REDPANDA_BROKERS value: "{{ .Release.Name }}-redpanda:9092" - name: CLICKHOUSE_ADDR value: "{{ .Release.Name }}-clickhouse:9000" - name: CLICKHOUSE_PASSWORD valueFrom: secretKeyRef: name: {{ .Release.Name }}-clickhouse key: password {{- if and .Values.enterprise.enabled .Values.ingest.requireTenantCredential }} # Enables ingest/internal/grpcserver.TenantResolver. # Deliberately its OWN opt-in, not folded into # enterprise.enabled directly (same reasoning # api.yaml/enterprise-api.yaml's ENTERPRISE_AUTH_URL isn't # set just because enterprise.enabled is true -- see that # env var's own comment there): turning this on requires # every agent to already present a valid `Authorization: # Bearer ` (minted via `enterprise-auth # -create-ingest-credential-tenant=`) or be refused # outright, which would silently break ingest for any # not-yet-reconfigured agent if it defaulted on alongside # enterprise.enabled. Off (the default) leaves every record # without a tenant_id header, same as every Phase 0-3 # deployment. - name: ENTERPRISE_AUTH_URL value: "http://{{ .Release.Name }}-enterprise-auth:8082" {{- end }} ports: - name: grpc containerPort: 4317 {{- if .Values.ingest.tlsSecretName }} volumeMounts: - name: tls mountPath: /etc/sentry-ingest readOnly: true {{- end }} resources: {{- toYaml .Values.ingest.resources | nindent 12 }} {{- if .Values.ingest.tlsSecretName }} volumes: - name: tls secret: secretName: {{ .Values.ingest.tlsSecretName }} {{- end }} --- apiVersion: v1 kind: Service metadata: name: {{ .Release.Name }}-ingest labels: {{- include "sentry.labels" . | nindent 4 }} {{- include "sentry.selectorLabels" (list $ "ingest") | nindent 4 }} spec: selector: {{- include "sentry.selectorLabels" (list $ "ingest") | nindent 4 }} ports: - name: grpc port: 4317